The ransomware crew that hit a thousand targets was allegedly run by a 16-year-old
The person police believe was running KillSec is 16. Spanish officers arrested him in Alicante on 30 September, and Eurojust says he was the group's main operator, the one who ran the leak site and decided who got squeezed next. A second suspect, the developer, has only just turned 18 and was a minor for part of it.
The operation was called KillSwitch. Nine countries took part, coordinated out of Hamburg by Eurojust and Europol, with Bitdefender and Group-IB helping on the technical side. Eight houses were searched across Spain, Greece, Romania and the UK, three people were arrested, and police seized five servers holding roughly 110 terabytes of stolen files. The dark web site where KillSec published that data is now in police hands.
KillSec appeared in 2024 and ran close to a thousand attacks, about half of which worked. Victims included hospitals, government bodies and financial firms. The way in was rarely clever: badly secured access points, often cloud storage left open to anyone who looked. Steal the files, send the victim a sample as proof, threaten to publish.
None of this was pointed at home PCs, and that is worth saying plainly. But the business model is the same one that eventually reaches you: take the data, make the loss permanent, charge for the undo. The only thing that properly breaks it is already having your own copy. Tendvane's one-click backup copies Documents, Pictures and Desktop to a drive you choose, which is about five minutes of work against the one threat where preparation is the entire defence.